Independent External Audit

3rd Party Audit / Third Party Risk Assessment

Assessment and audit of vendor and third-party risk to protect your organization from breaches that arrive through the supply chain.

We evaluate the security posture of vendors and third parties connected to your systems per SAMA and NCA requirements, and build a continuous third-party risk management process — from pre-contract due diligence to periodic monitoring — to reduce one of the largest sources of indirect breaches.

What's included

  • Inventory vendors and third parties connected to systems or processing data and tier them by criticality and access level
  • Pre-contract due diligence through security questionnaires and review of certifications and evidence
  • Assess each party's security posture against SAMA and NCA requirements and supply-chain controls
  • Review the security clauses in contracts (right to audit, incident notification, data processing, secure exit)
  • Build a continuous monitoring process and periodic reassessment cadenced to each vendor's risk level
  • Address fourth-party risk, vendor concentration and over-reliance on a single provider

Methodology & standards

01

Inventory and tiering: build the vendor register and classify by criticality, data type and access level

02

Screening and assessment: issue questionnaires, review evidence and assess each party against the reference framework

03

Risk analysis: identify each vendor's gaps, rate its risk and tie it to the impact on your business

04

Contractual remediation: draft binding security requirements and a remediation plan for each high-risk party

05

Continuous monitoring: set a reassessment cycle, metrics and an alerting mechanism for material changes

Deliverables

  • A vendor register classified by criticality and risk level
  • Individual assessment reports per third party with gaps and a risk rating
  • A security questionnaire template and a vendor acceptance criteria matrix
  • Ready-to-insert contractual security clauses for vendor agreements and the data processing agreement
  • A third-party risk remediation plan with ownership and timelines
  • A continuous monitoring framework and policy with a reassessment calendar

Regulatory controls it satisfies

SAMA CSF (Third Party Cyber Security domain)
Assess vendor risk and comply with the central bank's outsourcing rules before contracting and during the service
NCA ECC-2:2024 (Third-Party and Cloud Computing Cybersecurity domain)
Apply third-party and cloud service provider controls to contracts and system connectivity
ISO/IEC 27001:2022 (Annex A supplier relationship controls)
Manage information security in supplier relationships and the ICT supply chain
PDPL
Data processor obligations and data processing agreements when personal data is shared with third parties

Typical timeline

The schedule depends on the number of vendors; an initial critical batch is usually assessed within two to four weeks, after which monitoring continues as a recurring process.

Common questions

Do we need to assess every vendor at the same depth?

No. We apply a risk-based approach; a critical vendor with broad data access undergoes a deeper assessment and more frequent reassessment than a low-impact supplier.

A vendor refuses the right-to-audit clause, what is the alternative?

We accept recognized alternatives such as a SOC 2 Type II report, a valid ISO 27001 certificate or a documented independent questionnaire, coupled with stronger incident-notification terms and monitoring indicators.